A deliberately vulnerable MCP server demonstrating API key exposure through hardcoding, plaintext logging, and returning secrets to the model, part of the OWASP MCP Top 10 security lab.
An intentionally vulnerable MCP server designed as a live demo target for the MCP Trust security scanner. It contains deliberate insecure patterns to demonstrate scanning capabilities.
An intentionally vulnerable MCP server for security training, simulating a fictional company with 28 vulnerable tools and 38 challenges to learn AI agent attack and defense.